Options
All
  • Public
  • Public/Protected
  • All
Menu

Hierarchy

  • Censor

Index

Properties

Static Readonly CENSOR_RESPONSE

CENSOR_RESPONSE: "****" = "****"

Static Private INTERNAL_CUSTOM_CENSORED_HEADERS

INTERNAL_CUSTOM_CENSORED_HEADERS: string[] = []

Static Private Readonly MAIN_CENSORED_HEADERS

MAIN_CENSORED_HEADERS: string[] = ["Authorization", "Cookie", "Proxy-Authorization"]

Static Private Readonly MAIN_CENSORED_OPTIONS

MAIN_CENSORED_OPTIONS: string[] = ["auth", "authentication", "basicAuth", "base64EncodedAuth", "certFilePassphrase", "credentials","pw", "pass", "password", "passphrase", "tv", "tokenValue"]

Basic censorship items - list definitions & initialiazations, etc. *

Static Private Readonly MAIN_SECURE_PROMPT_OPTIONS

MAIN_SECURE_PROMPT_OPTIONS: string[] = ["keyPassphrase", "password", "passphrase", "tokenValue", "user"]

Static Readonly NULL_SESS_OBJ_MSG

NULL_SESS_OBJ_MSG: "Null session object was passed to API" = "Null session object was passed to API"

Static Private Readonly SECURE_ENV_NAME_PATTERN

SECURE_ENV_NAME_PATTERN: RegExp = /PASS|TOKEN|SECRET|KEY|CRED|AUTH/i

Static Private mCensoredOptions

mCensoredOptions: Set<string> = new Set([...this.DEFAULT_CENSORED_OPTIONS,...this.DEFAULT_CENSORED_HEADERS,...this.CUSTOM_CENSORED_HEADERS])

Static Private mConfig

mConfig: Config = null

Static Private mSchema

Singleton implementation of an internal reference to the schema

Accessors

Static CENSORED_OPTIONS

  • get CENSORED_OPTIONS(): string[]

Static CUSTOM_CENSORED_HEADERS

  • get CUSTOM_CENSORED_HEADERS(): string[]

Static DEFAULT_CENSORED_HEADERS

  • get DEFAULT_CENSORED_HEADERS(): string[]

Static DEFAULT_CENSORED_OPTIONS

  • get DEFAULT_CENSORED_OPTIONS(): string[]

Static SECURE_PROMPT_OPTIONS

  • get SECURE_PROMPT_OPTIONS(): string[]

Static profileSchemas

Methods

Static addCensoredHeader

  • addCensoredHeader(header: string): void

Static Private addCensoredOption

  • addCensoredOption(option: string): void

Static censorCLIArgs

  • censorCLIArgs(args: string[]): string[]

Static censorCommandLine

  • Copy and censor a raw command-line string before logging/printing.

    This is resilient to the different ways a user may supply a sensitive option on the command line:

    • space separated (--password secret)
    • equals separated (--password=secret)
    • single-dash short form / aliases (-p secret / -p=secret)

    When the parsed command arguments are supplied, the literal value of every secure option is additionally masked wherever it appears in the string. This catches secure values that contain embedded whitespace (e.g. a quoted --password "two words", which arrives here as --password two words once the shell has stripped the quotes) that a token-based regex cannot reliably match.

    Parameters

    • commandLine: string

      The raw command-line string to censor

    • Optional args: ICommandArguments

      The parsed command arguments, if available

    Returns string

    • The censored command-line string

Static censorEnvVariables

  • censorEnvVariables(env?: ProcessEnv): string
  • Copy and censor environment variables before logging/printing.

    Environment variables frequently hold credentials - Zowe explicitly supports supplying secure option values this way (e.g. ZOWE_OPT_PASSWORD, ZOWE_OPT_TOKEN_VALUE), and unrelated secrets (AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, etc.) commonly share the same environment. Because these values never pass through the CLI-argument censoring path, every variable whose name matches a credential pattern is redacted here. The serialized result is additionally routed through Censor.censorRawData so that any config-derived secure values are masked as well.

    Parameters

    • Default value env: ProcessEnv = process.env

      the environment to censor (defaults to process.env)

    Returns string

    • a censored, pretty-printed JSON string of the environment

Static censorObject

  • censorObject(data: Record<string, any>): Record<string, any>
  • Copy and censor any sensitive CLI arguments before logging/printing

    Parameters

    • data: Record<string, any>

      the data to censor

    Returns Record<string, any>

    • the censored data

Static censorRawData

  • censorRawData(data: string, category?: string): string
  • Copy and censor any sensitive CLI arguments before logging/printing

    Parameters

    • data: string

      the data to censor

    • Default value category: string = ""

    Returns string

    • the censored data

Static censorSession

  • censorSession(sessObj: any): string
  • Censor sensitive data from an session object or a sub-object of a session. The intent is to create a copy of the object that is suitable for logging.

    Parameters

    • sessObj: any

      A Session object (or ISession, or availableCreds) to be censored.

    Returns string

    • The censored object as a string.

Static censorYargsArguments

  • censorYargsArguments(args: Arguments): Arguments

Static Private escapeRegExp

  • escapeRegExp(value: string): string
  • Escape every regular-expression metacharacter in a string so it can be safely embedded in a RegExp as a literal. Secure values and option names are user-supplied and can frequently contain these characters.

    Parameters

    • value: string

      The literal string to escape

    Returns string

    • The escaped string, safe to pass to new RegExp

Static Private handleSchema

Static isSecureEnvName

  • isSecureEnvName(name: string): boolean
  • Determine whether an environment-variable name indicates a sensitive value.

    Parameters

    • name: string

      the environment-variable name to test

    Returns boolean

    • True if the variable should be redacted; False otherwise

Static isSecureValue

  • isSecureValue(prop: string): boolean

Static isSpecialValue

  • isSpecialValue(prop: string): boolean
  • Specifies whether a given property path (e.g. "profiles.lpar1.properties.host") is a special value or not. Special value: Refers to any value defined as secure in the schema definition. These values should be already masked by the application (and/or plugin) developer.

    Parameters

    • prop: string

      Property path to determine if it is a special value

    Returns boolean

    True - if the given property is to be treated as a special value; False - otherwise

Static Private mCensorObject

  • mCensorObject(data: Record<string, any>, secureValues: any[]): Record<string, any>

Static Private replaceValsInSess

  • replaceValsInSess(sessObj: any, createCopy: boolean): string
  • Recursively replace sensitive data in an session-related object and any relevant sub-objects.

    Parameters

    • sessObj: any

      A Session object (or ISession, or the availableCreds) to be censored.

    • createCopy: boolean

    Returns string

    • The censored object as a string.

Static setCensoredOptions

  • Generate and set the list of censored options. Attempt to source the censored options from the schema, config, and/or command being executed.

    Parameters

    • Optional censorOpts: ICensorOptions

      The objects to use to gather options that should be censored

    Returns void

Static setProfileSchemas

Generated using TypeDoc